What happened
In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.
How the deception worked
The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.
AI involvement · No AI reported
No AI element reported; the kit relayed credentials to operators via Telegram in real time.
The control that would have caught it· our reading, not a claim from the sources
SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.
Sources (4)
- Detecting Scatter Swine: Insights into a Relentless Phishing CampaignOkta Security·sec.okta.comOpen ↗
- Twilio confirms data breach after its employees got phishedHelp Net Security·helpnetsecurity.comOpen ↗
- Twilio says breach also compromised Authy two-factor app usersTechCrunch·techcrunch.comOpen ↗
- Incident Report: Employee and Customer Account CompromiseTwilio·twilio.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.